6SHR system from Gether Technology does not properly validate the specific page parameter, allowing remote attackers with regular privilege to inject SQL command to read, modify, and delete database contents.
References
Link | Resource |
---|---|
https://www.twcert.org.tw/en/cp-139-8034-657b7-2.html | Vendor Advisory |
https://www.twcert.org.tw/tw/cp-132-8030-e2eac-1.html | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2024-08-30 03:15
Updated : 2024-09-05 13:40
NVD link : CVE-2024-8329
Mitre link : CVE-2024-8329
CVE.ORG link : CVE-2024-8329
JSON object : View
Products Affected
6shr_system_project
- 6shr_system
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')